Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Itechscripts Real Estate Script16/7/202217/6/2026
A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The…
ModificadaCrítica (9.3)1.4%—Realestate Project Realestate11/7/202217/6/2026
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (4.8)0.59%—Simple Real Estate Pack Project Simple Real Estate Pack30/5/202217/6/2026
The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)1.5%—Simple Real Estate Portal System Portal Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.
ModificadaCrítica (9.8)1.5%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.
ModificadaCrítica (9.8)1.3%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate.
ModificadaCrítica (9.8)1.3%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.
ModificadaCrítica (9.8)1.2%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
ModificadaCrítica (9.8)1.2%—Simple Real Estate Portal System Project Simple Real Estate Portal System2/3/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
ModificadaMedia (6.1)3.7%💥 ExploitContempothemes Real Estate 76/7/202117/6/2026
The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context
ModificadaAlta (8.8)0.82%—Realestateconnected Easy Property Listings18/2/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.2)1.0%—Advanced Real Estate Script Project Advanced Real Estate Script5/1/202017/6/2026
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
ModificadaMedia (6.1)0.70%—Advanced Real Estate Script Project Advanced Real Estate Script5/1/202017/6/2026
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
ModificadaMedia (6.1)1.00%—Realestateconnected Easy Property Listings30/8/201917/6/2026
The easy-property-listings plugin before 3.4 for WordPress has XSS.
ModificadaMedia (5.3)1.5%—Open Source Real-estate Script Project Open Source Real-estate Script4/10/201817/6/2026
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
ModificadaMedia (5.4)0.55%—Advanced Real Estate Script Project Advanced Real Estate Script10/8/201817/6/2026
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
ModificadaMedia (6.5)0.94%—Advanced Real Estate Script Project Advanced Real Estate Script10/8/201817/6/2026
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile.
ModificadaAlta (8)0.45%—Advanced Real Estate Script Project Advanced Real Estate Script10/8/201817/6/2026
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
ModificadaAlta (7.5)1.0%—Csa-estate Csatoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for CSAToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)2.0%💥 ExploitOS Property Real Estate Project OS Property Real Estate22/2/201817/6/2026
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.
ModificadaCrítica (9.8)2.7%💥 ExploitComdev Jomestate PRO17/2/201817/6/2026
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
ModificadaMedia (5.4)0.54%—Multilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script7/2/201817/6/2026
PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
ModificadaCrítica (9.8)3.0%💥 ExploitMultilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script29/1/201817/6/2026
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
ModificadaMedia (4.8)0.49%—Advanced Real Estate Script Project Advanced Real Estate Script3/1/201817/6/2026
Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
ModificadaMedia (4.8)0.49%—Advanced Real Estate Script Project Advanced Real Estate Script3/1/201817/6/2026
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.